Towards Integrated Modelling of Dynamic Access Control with UML and Event-B
Software Engineering
2018-05-16 v1 Logic in Computer Science
Abstract
Role-Based Access Control (RBAC) is a popular authorization model used to manage data-access constraints in a wide range of systems. RBAC usually defines the static view on the access rights. However, to ensure dependability of a system, it is often necessary to model and verify state-dependent access rights. Such a modelling allows us to explicitly define the dependencies between the system states and permissions to access and modify certain data. In this paper, we present a work-in-progress on combining graphical and formal modelling to specify and verify dynamic access control. The approach is illustrated by a case study -- a reporting management system.
Keywords
Cite
@article{arxiv.1805.05521,
title = {Towards Integrated Modelling of Dynamic Access Control with UML and Event-B},
author = {Inna Vistbakka and Elena Troubitsyna},
journal= {arXiv preprint arXiv:1805.05521},
year = {2018}
}
Comments
In Proceedings IMPEX 2017 and FM&MDD 2017, arXiv:1805.04636